Weaknesses of type CWE-200

4,959 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-44820HIGHA sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/EPSS 0.4%CVE-2024-20937MEDIUMVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC). Supported verEPSS 0.4%CVE-2025-5184MEDIUMSummer Pearl Group Vacation Rental Management Platform HTTP Response Header information disclosureEPSS 0.4%CVE-2026-44784MEDIUMDiscourse: Non-staff group owners can see email password in plaintext through group historyEPSS 0.4%CVE-2026-19300HIGHLangflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flowsEPSS 0.4%CVE-2026-14898MEDIUMThe OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect promEPSS 0.4%CVE-2025-2840MEDIUMDAP to Autoresponders Email Syncing <= 1.0 - Unauthenticated Information ExposureEPSS 0.4%CVE-2026-36539HIGHNetis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configuration as a JSON respEPSS 0.4%CVE-2026-43992CRITICALJunoClaw: MCP write tools exposed raw BIP-39 mnemonic as a tool-call parameterEPSS 0.4%CVE-2026-70943HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2025-63205HIGHAn issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 PEPSS 0.4%CVE-2026-54305HIGHn8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE EndpointsEPSS 0.4%CVE-2026-59288HIGHSpring for GraphQL Information Exposure in GraphiQL supportEPSS 0.4%CVE-2023-33851MEDIUMIBM PowerVM Hypervisor information disclosureEPSS 0.4%CVE-2026-14820MEDIUMQuiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz LoginEPSS 0.4%CVE-2024-6553MEDIUMWP Meteor Website Speed Optimization Addon <= 3.4.3 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-6566MEDIUMAramex Shipping WooCommerce <= 1.1.21 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-6545MEDIUMAdmin Trim Interface <= 3.5.1 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-2916MEDIUMJeg Kit for Elementor <= 3.1.1 - Authenticated (Contributor+) Exposure of Sensitive Information via 'JkitDashboardOption' Inline ScriptEPSS 0.4%CVE-2025-25333HIGHAn issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.EPSS 0.4%